Privacy Policy
Last updated: March 2026
Introduction
LowTox AI ("we", "our", or "us") provides a browser extension and web service that analyses product ingredient lists and returns safety assessments. This policy describes what data we collect, how we use it, and your rights regarding your personal data. We process data in accordance with the UK GDPR and other applicable privacy laws.
Data we collect
Ingredient text and analysis results. When you use the extension to analyse a product, we receive the ingredient list you submit. We process this via AI services (see Third-party processors below) to generate a verdict (SAFE, CAUTION, or AVOID) and summaries. We cache analysis results in our database to speed up repeat checks for the same product. Cached results are stored by ingredient hash (not by your identity). We do not log, sell, or share this data with third parties for marketing or advertising purposes.
Concern profiles. You may optionally set concern preferences (e.g. fragrance-free, pregnancy-safe, endocrine disruptors). In the extension, these are stored locally in your browser (browser.storage). If you are signed in and use features that sync your profile to our servers, we may store your concern preferences in our database to personalise analyses. Concern profiles may include information about health sensitivities or preferences that could be considered special category data under GDPR Article 9. We process this only with your explicit consent and for the purpose of providing personalised analyses.
Account and session data. If you access password-protected areas (e.g. the web installer), we may store session information to verify access. We do not use this for profiling or marketing.
How we use your data
- To generate ingredient safety assessments and personalised verdicts
- To cache results and improve response times for repeat analyses
- To provide and improve our services
- To comply with legal obligations
Third-party processors
We use OpenAI and optionally Perplexity to process ingredient text and generate assessments. Ingredient lists and, where applicable, your concern profile text may be sent to these providers. They process data under their respective privacy policies and data processing terms. We do not use these services for advertising or profiling beyond the analysis itself.
Data retention
Cached analysis results are retained to support repeat checks. You may request deletion of your concern profile at any time (see Your rights). We will delete or anonymise data in accordance with our retention policy and applicable law.
Your rights
Under UK GDPR and applicable law, you have the right to:
- Access: request a copy of your personal data
- Rectification: correct inaccurate data
- Erasure: request deletion of your data (including your concern profile)
- Restrict processing: in certain circumstances
- Object: to processing based on legitimate interests
- Data portability: receive your data in a structured format
To exercise these rights, contact us (see Contact below). You also have the right to complain to a supervisory authority, such as the Information Commissioner's Office (ICO) in the UK.
Cookies and similar technologies
Our web installer and website may use cookies or local storage for session management and essential functionality. We do not use tracking cookies for advertising.
Security
We implement technical and organisational measures to protect your data against unauthorised access, loss, or misuse. Data is transmitted over HTTPS. We regularly review our security practices.
Changes to this policy
We may update this policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. Continued use of our services after changes constitutes acceptance of the updated policy.
Contact
For privacy-related enquiries or to exercise your rights, please contact us at the address or email provided on our website.